Last week, we announced our IPAbuseCheck lookup tool. We see lots of infected/abusive hosts on the Internet attempting to proxy abusive web transactions through our proxies. Rather than just ignoring these transactions, we’ve decided to provide this lookup utility for security professionals and organizations to query and identify abusive/infected hosts within their networks – based on some feedback, the service has been well received. This follow-up post provides a brief summary of the top offenders that we see in our database to date (July 1 – October 25, 2011).
Top Abuse Breakdown by GeographyThe top 15 countries account for over 75% of the abusive clients that we have seen- with the US, China, Russia, Germany, Venezuela, and India accounting for half of the abusive clients that we have seen to date.
Top Abuse Breakdown by Organization (ASN)
|ASN by Abusive Clients||ASN by Abusive Transactions|
It was interesting to see some well known organizations like Amazon and Microsoft near the top for organizations that have sent us the most abusive transactions. Rather than these being infected corporate systems, it appears to be a handful of hosting service systems that are being abused either directly from the customer or from an infection. Here is a snapshot of a report from our database of a Microsoft IP that we reported to their Abuse Dept. once we started digging into this data:
Screenshot of 220.127.116.11 Abuse Report
The transactions observed were hundreds of thousands of brute-force attempts against file sharing sites like Megaupload, Hotfile, Filesonic, and Rapidshare.
Top Abuse Breakdown by ClientClients in our database that have the longest time range of abuse seen tend to be those clients that are scanning the Internet looking for open web proxies. These were the top 5 clients that we have seen with the longest date range from:
Top 5 Abusive Hosts by Date Range
|Host||First Seen||Last Seen||Behavior|
|18.104.22.168||07/01/11 07:00||10/25/11 06:54||Proxy Scanning|
|22.214.171.124||07/01/11 07:00||10/25/11 06:51||Proxy Scanning|
|126.96.36.199||07/01/11 07:06||10/25/11 06:57||Proxy Scanning|
|188.8.131.52||07/01/11 07:07||10/25/11 06:56||Proxy Scanning|
|184.108.40.206||07/01/11 07:08||10/25/11 06:54||Proxy Scanning|
The following table lists the top 5 abusive hosts by transaction count – these tend to be hosts that attempt to forward bulk transactions through proxies, like forum spam and brute-force attempts. Related to the previous section of organizations with the top abusive transactions – you can see that two Amazon EC2 systems (220.127.116.11, 248) are at the top of the list.
Top 5 Abusive Hosts by Transactions
Top Web Services Targeted in AbuseThe following lists the top 5 most targeted web sites/services abused by number of transactions and number of unique abusing clients.
Top 5 Abused Web Services by:
The bulk of the top sites by transaction are forum spam sites – in the top instances, the forums being abused are in Vietnam. One brute-forcing target is in the top 5, which is the Rapidshare file host. The bulk of the top services being used/abused by number of clients are proxy checkers – the Chinese service sina.com.cn was also listed in the top as a spam bot / brute-forcing target.
The above post provides some insight into the types of information that can be extracted from this service, and we’ll continue to update the database regularly with the latest abusing clients.
Leave a reply